Spain's AI law 2026: what your SMB needs to know before August

Spain's AI Law 2026: What Your SMB Needs to Know Before August

The government approved the Organic Law for the proper use and governance of artificial intelligence in late May. Sounds like something distant, the kind of issue that only affects big tech companies. But it doesn't. If you use ChatGPT to draft emails, have a WhatsApp chatbot, or any automation tool talking with your customers, this law directly affects you.

Spain's AI Law (Organic Law for proper use and governance of artificial intelligence) is the rule adapting the EU AI Regulation to Spanish law. It establishes transparency, literacy, and data protection obligations for any company using AI, with fines up to €35 million. AESIA (Spanish AI Supervision Agency) is the enforcement body, based in A Coruña.

The problem is most Spanish SMBs don't know this yet. According to Spain's statistics agency, over half of service companies already use some form of AI tool. Very few have done their homework to comply with the regulation arriving this August.

Let's see what exactly changes, what you need to do, what can happen if you don't, and how to prepare without needing a 10-person legal team.

Spain's AI Law vs. EU AI Regulation: they're not the same

Two regulations intersect here, and it's worth not confusing them:

In practice, Spain's law is who watches you. Who issues the fine. Who decides whether your chatbot complies. The EU Regulation makes the rules; Spain's law enforces them with names and penalties.

The enforcement body is AESIA (Spanish AI Supervision Agency), based in A Coruña. Spain was the first EU country to create a specific agency for this, which tells you how serious it is.

Key regulatory dates

This isn't something coming "someday." It's here now:

DateWhat comes into forceImpact for your SMB
August 1, 2024EU AI Regulation enters into forceRegulatory clock starts
February 2, 2025Prohibition of unacceptable practices + AI literacy requirementYour team must understand the risks of the AI tools they use
August 2, 2025General-purpose model obligations (GPT, Claude, Gemini...)Providers must comply; affects how you use them
August 2, 2026Full application: AESIA inspects and finesCritical date. Everything must be documented
August 2, 2027AI in regulated products (CE marking)Manufacturers and integrators in specific sectors

There it is: August 2, 2026—less than two months after reading this—AESIA starts real inspections. What isn't documented by then can cost you money.

There's debate about whether the Digital Omnibus, a European regulatory revision approved by Parliament in March 2026, will delay some obligations until December 2027. But even then, AI literacy requirements (Article 4) and prohibited practices remain in force. And until the EU Council formally adopts the text, August 2026 is the legal deadline.

Who does the law affect?

It affects any company, including freelancers, that uses, develops, or deploys AI systems: chatbots, virtual assistants, content generators, automated decision tools, biometric analysis systems, and much more.

Concrete examples that read like a catalog of what any SMB does today:

If you use AI and run a business in Spain, the law is for you. Whether you have 1 or 500 employees.

The 4 concrete obligations you should already be meeting

Not all the regulation applies equally to everyone. Real obligations depend on the risk level of the system you use. But four apply to basically any SMB:

Obligation 1: Transparency—your customers must know they're talking to AI

If you have a chatbot or virtual assistant, customers must know they're interacting with a machine, not a person. This was already best practice under the EU Regulation since August 2024. Now, with Spain's law, it's directly auditable.

A small footnote isn't enough. The disclosure must be clear and understandable. If your chatbot says "Hi, I'm Maria, your assistant" and it's AI, you're in breach.

Obligation 2: AI literacy—your team must understand what they're using

Article 4 of the EU Regulation has required since February 2025 that your team members using AI tools have sufficient understanding of the risks, limitations, and legal framework of those systems.

Translated: it's not enough that your employee can use ChatGPT. They need to understand what can go wrong, the risks of feeding customer data to third-party tools, and when AI hallucinates.

This is auditable from August 2026. AESIA can ask for documentation of trainings: who trained, when, on what tools, and how you decided on content and duration.

Obligation 3: Data protection in your AI tools

Many freelancers and SMBs feed customer information—names, addresses, order data, contracts—into tools like ChatGPT, Claude, or Gemini without reading privacy policies. Sometimes to draft a response, sometimes to analyze data.

The law makes clear: you're responsible for that data. You need to know:

Obligation 4: High-risk systems—documentation, assessment, human oversight

If your AI makes decisions affecting people—hiring, credit scoring, service access, medical diagnosis—obligations multiply. In these cases you need:

This especially affects SMBs in HR, fintech, health, and insurance. If that's you, August isn't a date—it's an emergency.

Fines: up to €35 million (or 7% of global revenue)

The penalty regime has three tiers:

Violation typeMaximum fine
Prohibited practices (biometrics in public spaces, subliminal manipulation...)€35 million or 7% of global revenue
High-risk obligation breaches€15 million or 3% of global revenue
Incorrect information to authority€7.5 million or 1.5% of global revenue
Minor violations (missing documentation, undemonstrated literacy...)€6,000 to €500,000

Does this mean a hair salon gets fined €35 million? No. The law applies proportionality by company size. But minor violations start at €6,000, which for a freelancer or microenterprise does hurt.

Most important: in an inspection, undocumented literacy or lack of chatbot transparency can open the door to reviewing everything else. One minor breach can escalate any other violations they find.

Action plan: what to do in the next 60 days

We're not going to tell you to hire a law firm for €15,000. Most SMBs can meet basic requirements with an orderly approach. Here's a realistic plan:

Weeks 1-2: Take inventory

Spend 30 minutes writing down every AI tool you use. Think about:

For each, note: what it does, what data you feed it, who provides it, and where their servers are.

Weeks 2-3: Review transparency

If you have chatbots or virtual assistants, verify the customer knows they're talking to AI. Change the avatar name if needed, add a notice, ensure the escalation path to a human is clear and accessible.

Also review each tool's data usage policies. ChatGPT Plus, for example, lets you disable data use for training (Settings > Data Controls). Do it if you haven't.

Weeks 3-4: Document literacy

You don't need an AI master's degree. Just document that your team (or you, if freelance) received basic training on:

An internal email with these guidelines, a documented 30-minute talk with date and attendees, or a saved online course as PDF works. Don't seek perfection; just show you acted.

Weeks 4-6: Establish protocols

Create an internal document—even two pages—with:

Your AI usage policy: what tools are approved, what data can and can't go in, who's responsible for each tool, what to do if something fails.

Your transparency policy: how you identify AI to customers, when you escalate to humans, how you inform the user.

Keep invoices for all your AI tools. You'll need them to justify professional use if asked.

Weeks 6-8: Review and adjust

Do a final pass. Do you have high-risk systems (automatic CVs, scoring, decisions about people)? If so, you need more robust technical documentation and impact assessment. Professional consultation might be worth it here.

Only using AI for productivity and basic support? You're at a reasonable compliance level with the plan above.

Tools that help

Specific ones for compliance without losing your mind:

Frequently asked questions

If I only use free ChatGPT for email drafts, do I have to do all this?

For basic productivity use (writing, research, summaries), your obligations are mainly three: don't feed customer sensitive data, make sure generated content is reviewed before sending, ensure your team knows these two things. Literacy applies whether free or paid.

Does my WhatsApp chatbot (Tidio, ManyChat...) count?

Yes. Any system interacting with customers using AI and potentially making automated decisions (routing queries, generating answers, collecting data) is in scope. Make sure your chatbot provider also complies: if using an intermediary like Tidio or ManyChat, review their compliance documentation.

Are there exemptions for microenterprises or freelancers?

No total exemption. The law applies to all. But the penalty regime accounts for company size, severity, and intent. Fines will be proportional. Don't use that as an excuse to do nothing.

Can I use the AI Act or Spain's law to shield myself if AI gives a customer wrong information?

The law reinforces your responsibility as a business. If a chatbot gives incorrect information to a customer based on data you provided, you're liable. That's why human oversight and verification are mandatory, not optional.

Does the Digital Kit cover AI Law compliance?

The 2026 Digital Kit includes a new "AI applied to work" category with grants up to €2,000–€3,000 for freelancers and microenterprises. This can fund part of implementing tools to help you comply. Check acelerapyme.gob.es. The complete guide to Digital Kit and Consulting Kit explains how to combine both grants.

Request a free assessment

If you want to implement this in your business, request a free 30-minute assessment. Contact us here or reach out via WhatsApp from the site.